북한 해킹 단체 APT 37((리퍼,Reaper)에서 만든 RokRAT 악성코드-250615_양곡판매소 운영 현황.hwp(2025,06,18)

2025-08-11 Sakai RokRAT malware created by North Korean hacking group APT37/Reaper: grain sales office operations status HWP

https://wezard4u.tistory.com/429564

Thumbnail for 북한 해킹 단체 APT 37((리퍼,Reaper)에서 만든 RokRAT 악성코드-250615_양곡판매소 운영 현황.hwp(2025,06,18)

A Korean malware analysis attributes a malicious HWP document named “250615_Grain Sales Office Operations Status.hwp” to APT37/Reaper and describes it as RokRAT-themed activity. The lure content concerns grain sales and distribution in Pyongyang, indicating likely targeting of people working on North Korea-related issues or research. The document embeds a Proton Drive hyperlink and OLE objects that drop ShellRunas.exe and credui.dll into the TEMP directory when the relevant page is accessed. Infection depends on the user approving the ShellRunas.exe execution prompt, and the write-up also records a Dropbox-hosted Father.jpg URL that could not be further analyzed because the files were no longer downloadable.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 47c1cfc2380c3fa6c8283160707544fb 2025-08-11 2025-08-11
HASH f20674ffc0267222555a0a23b580ee0… 2025-08-11 2025-08-11
HASH 71620bd3d6462e901324f08e97bebd0… 2025-08-11 2025-08-11
URL https://drive.proton.me/urls/DM… 2025-08-11 2025-08-11
URL https://drive.proton.me/urls/DM… 2025-08-11 2025-08-11
URL https://dl.dropboxusercontent.c… 2025-08-11 2025-08-11
IPv4 217.60.37.55 2025-08-08 2025-08-11

Related Actors

Related Reports

« Back